Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: mesamit on February 28, 2012, 10:59:33 AM

Title: avast detects mbamswissarmy.sys file as a rootkit
Post by: mesamit on February 28, 2012, 10:59:33 AM
i think mbamswissarmy.sys file is a part of malwarebytes antimalware.....and avast detects it as a rootkit...i have attach image along with the post....
Title: Re: avast detects mbamswissarmy.sys file as a rootkit
Post by: CraigB on February 28, 2012, 11:12:45 AM
You can and maybe should add the MBAM program file to the exclusions list in file system shield and settings exclusions, iv had no detections yet myself but with the new avast 7's ability to scan more thoroughly it might be a wise idea - thats if your using version 7 anyway but i still think its better to exclude both programs from each other for compatibility and it may even make your system run lighter.
Title: Re: avast detects mbamswissarmy.sys file as a rootkit
Post by: AdrianH on February 28, 2012, 11:14:35 AM
There are instructions for ruinning avast and Malwarebytes together at the Malwarebytes forum. With the correct exceptions set there are no conflicts.
Title: Re: avast detects mbamswissarmy.sys file as a rootkit
Post by: CraigB on February 28, 2012, 11:20:43 AM
There are instructions for ruinning avast and Malwarebytes together at the Malwarebytes forum. With the correct exceptions set there are no conflicts.
That would be here http://forums.malwarebytes.org/index.php?act=findpost&pid=417798 scroll to section k.
Title: Re: avast detects mbamswissarmy.sys file as a rootkit
Post by: claprood on February 28, 2012, 03:42:27 PM
I have mbam but not that sys file so maybe you should scan it here just to be sure
https://www.virustotal.com/
Title: Re: avast detects mbamswissarmy.sys file as a rootkit
Post by: DavidR on February 28, 2012, 04:29:41 PM
The problem being, excluding that file or MBAM files wouldn't change this detection as it is the anti-rootkit scan and doesn't use the conventional signatures or exclusions (I believe).

So there is little point in uploading to virustotal as it can't replicate the anti-rootkit scan.

I have avast and MBAM Pro installed on this xp pro system and avast isn't alerting on the mbamswissarmy.sys file (if that is the one in the alert image as it isn't shown).